CVE Vulnerabilities

CVE-2019-11733

Improper Authentication

Published: Sep 27, 2019 | Modified: Aug 24, 2020
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
9.8 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

When a master password is set, it is required to be entered again before stored passwords can be accessed in the Saved Logins dialog. It was found that locally stored passwords can be copied to the clipboard thorough the copy password context menu item without re-entering the master password if the master password had been previously entered in the same session, allowing for potential theft of stored passwords. This vulnerability affects Firefox < 68.0.2 and Firefox ESR < 68.0.2.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla * 68.0.2 (excluding)
Firefox_esr Mozilla * 68.0.2 (excluding)
Red Hat Enterprise Linux 6 RedHat firefox-0:60.9.0-1.el6_10 *
Red Hat Enterprise Linux 7 RedHat firefox-0:60.9.0-1.el7_7 *
Red Hat Enterprise Linux 8 RedHat firefox-0:68.1.0-1.el8_0 *
Firefox Ubuntu bionic *
Firefox Ubuntu devel *
Firefox Ubuntu disco *
Firefox Ubuntu upstream *
Firefox Ubuntu xenial *

Potential Mitigations

References